Notification

Icon
Error

7-Zip Arbitrary Code Execution Vulnerability Check

Posted: Friday, May 4, 2018 2:13:36 PM(UTC)
Esben.D

Esben.D

Member Administration Original PosterPosts: 1,834
6
Like
Update 7th of May, posted a different report that is immune to conversion errors: due to the high variance in the formatting of 7-zip version numbers our previous report could cause conversion errors in certain installations. The new report lists all computers that don't have the current latest version of 7-zip installed (18.05), but will need to be adjusted when newer versions are released.

This report lists all computers which have an installation of a 7-Zip version lower than 18.05 and are vulnerable to the 7-Zip Arbitrary Code Execution Vulnerability. If vulnerable assets are found, you can patch them by using the steps in the 7-Zip Arbitrary Code Execution Vulnerability Announcement.

To run this report, do the following:
  • Open the report builder in the Lansweeper web console under Reports/Create New Report.
  • Paste the SQL query (report) found below at the bottom of the page, replacing the default SQL query.
  • Left-click somewhere in the upper section of the page so the query applies.
  • Give the report a title.
  • Hit the Save & Run button to save the report. Export options are listed on the left.
Code:
Select Top 1000000 tblAssets.AssetID,
tblAssets.AssetName,
tblAssets.Domain,
tblAssets.Username,
tblAssets.Userdomain,
Coalesce(tsysOS.Image, tsysAssetTypes.AssetTypeIcon10) As icon,
tblAssets.IPAddress,
tsysIPLocations.IPLocation,
tblAssetCustom.Manufacturer,
tblAssetCustom.Model,
tsysOS.OSname As OS,
tblAssets.SP,
tblAssets.Lastseen,
tblAssets.Lasttried,
tblSoftwareUni.softwareName As Software,
tblSoftware.softwareVersion As Version,
tblSoftwareUni.SoftwarePublisher As Publisher,
tblSoftware.Lastchanged
From tblAssets
Inner Join tblAssetCustom On tblAssets.AssetID = tblAssetCustom.AssetID
Inner Join tsysAssetTypes On tsysAssetTypes.AssetType = tblAssets.Assettype
Inner Join tsysIPLocations On tsysIPLocations.LocationID =
tblAssets.LocationID
Inner Join tblState On tblState.State = tblAssetCustom.State
Inner Join tblSoftware On tblAssets.AssetID = tblSoftware.AssetID
Inner Join tblSoftwareUni On tblSoftwareUni.SoftID = tblSoftware.softID
Left Join tsysOS On tsysOS.OScode = tblAssets.OScode
Where tblSoftwareUni.softwareName Like '%7-Zip%' And
tblSoftware.softwareVersion Not Like '%18.05%' And tblState.Statename =
'Active'
Order By tblAssets.Domain,
tblAssets.AssetName,
Software
Esben.D
#1Esben.D Member Administration Original PosterPosts: 1,834  
posted: 5/4/2018 2:22:00 PM(UTC)
If you have any questions regarding the report, please contact us via email at support@lansweeper.com

Active Discussions

Action Change Windows domain PC Name
by  max204   Go to last post Go to first unread
Last post: 9/19/2019 10:28:29 AM(UTC)
Lansweeper Launch PowerShell remote PSSession
by  Ian  
Go to last post Go to first unread
Last post: 9/9/2019 12:10:56 PM(UTC)
Action Remote print management
by  CyberCitizen   Go to last post Go to first unread
Last post: 9/4/2019 3:53:00 AM(UTC)
Lansweeper Infopath installer help
by  CyberCitizen  
Go to last post Go to first unread
Last post: 9/2/2019 8:18:06 AM(UTC)
Lansweeper Remote Registry 2019
by  EB   Go to last post Go to first unread
Last post: 8/22/2019 3:47:10 PM(UTC)
Lansweeper lspush smtp direct send
by  Danilo Ferrari  
Go to last post Go to first unread
Last post: 8/1/2019 1:39:26 PM(UTC)
Action Delete old user profiles
by  DaveDischord   Go to last post Go to first unread
Last post: 7/30/2019 6:18:28 PM(UTC)
Lansweeper Best way to delete multiple registries
by  Corcos  
Go to last post Go to first unread
Last post: 7/25/2019 8:18:23 PM(UTC)